โ† All AWS Flashcard Decks

Certified Solutions Architect VPC Networking and Security Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Certified Solutions Architect VPC Networking and Security flashcards as text
  1. A security team wants to inspect all traffic flowing between subnets in a VPC for intrusion detection. Which architecture pattern should be used?

    Answer: Route traffic through a Gateway Load Balancer with a fleet of inspection appliances

    A Gateway Load Balancer enables transparent network traffic inspection by distributing traffic to a fleet of third-party security appliances before forwarding it to the destination.

  2. Which AWS feature protects against DDoS attacks at Layers 3 and 4 automatically at no additional cost for all AWS customers?

    Answer: AWS Shield Standard

    AWS Shield Standard provides automatic protection against common Layer 3 and 4 DDoS attacks and is included at no extra cost for all AWS customers.

  3. A Solutions Architect needs to share a private service hosted in one VPC with consumers in other VPCs without VPC peering. What should they use?

    Answer: AWS PrivateLink

    AWS PrivateLink allows you to expose a service in one VPC to consumers in other VPCs via interface endpoints without peering or exposing traffic to the internet.

  4. What happens to network traffic when a security group rule is modified on a running EC2 instance?

    Answer: Changes apply immediately to all existing and new connections

    Security group rule changes are applied immediately and affect both existing and new connections because security groups are stateful and track connection state.

  5. A company needs a managed Site-to-Site VPN connection between their on-premises network and AWS. Which two components are required on the AWS side?

    Answer: Virtual Private Gateway and Customer Gateway

    A Site-to-Site VPN requires a Virtual Private Gateway (on the AWS side) and a Customer Gateway (representing the on-premises VPN device) to establish the connection.

  6. An architect is designing a multi-VPC network and wants to avoid overlapping CIDR blocks. Which CIDR range is INVALID for a VPC?

    Answer: 169.254.0.0/16

    The 169.254.0.0/16 range is the link-local address range reserved for AWS internal services like the instance metadata service and cannot be used for VPC CIDRs.

  7. Which AWS service provides a web application firewall to filter HTTP/HTTPS traffic based on rules like IP addresses, SQL injection, and cross-site scripting?

    Answer: AWS WAF

    AWS WAF (Web Application Firewall) filters HTTP/HTTPS web traffic using customizable rules to protect against common web exploits at Layer 7.